Contents Introduction ........................................................................................................................... 4 1. Outline/Overview ........................................................................................................... 4 1-1 Purpose of the guidelines............................................................................................ 4 1-2 Intended users ............................................................................................................. 4 1-3 Fundamental ideas of CII ........................................................................................... 5 1-4 Significance of CIIP .................................................................................................... 5 1-4-1 Purpose of CIIP ........................................................................................................ 5 1-4-2 Fundamental issues and concerns of CIIP............................................................. 5 1-5 Definition of terms ...................................................................................................... 6 2. Role of Governments and/or Regulators in CIIP ......................................................... 6 2-1 Preparation for development of CIIP policies ........................................................... 6 2-2 Establishment of information security policy or strategy........................................ 7 2-3 Establishment of guidelines for security standards ................................................. 7 2-4 Establishment of governance structure and identifying stakeholders ................... 8 2-4-1 Establishment of governance .............................................................................. 8 2-4-2 Roles and Responsibilities of stakeholders ........................................................ 9 2-5 Establishment of an information sharing scheme between the governments and/or regulators and private sector............................................................................................ 9 2-6 IT Security Crisis Management ............................................................................... 10 2-6-1 Incident handling ............................................................................................... 10 2-6-2 Disaster recovery and Business Continuity Planning (BCP) ..........................11 2-7 Cyber exercise ............................................................................................................11 2-7-1 Significance of cyber exercise .............................................................................11 2-7-2 Government support for industry-level exercises in the private sector ..........11 2-7-3 Government support for cross-industry exercises in the private sector ........ 12 2-8 Awareness-raising activities for CII owners/operators .......................................... 12 2-9 ASEAN regional partnership ................................................................................... 12

Select target paragraph3